AI News Feed
Market watch
Cybersecurity

Data breaches expose customer info at Framework and Valve's Steam hardware

Framework and European Steam hardware customers have been notified of separate data breaches exposing personal information, with no payment details compromised.

Framework, the maker of repairable and upgradeable computers, sent an email to all customers on August 6 stating that customer names, login IPs, addresses, phone numbers and emails were accessed in a hack of its business database provider Metabase. Payment information was not included in the breach. According to a blog on Metabase's website, the attacker used an unknown (0-day) vulnerability that Metabase has since identified and patched. Metabase said it is working with a third-party forensic investigation firm to understand the full nature and scope of the event.

Framework said it rotated its credentials after being notified of the breach and confirmed that there were no changes in admin access or access to systems outside of Metabase. The company also said it is reviewing and improving its methodology for data storage in external database vendors.

In a separate incident, Valve said that CEVA Logistics, the company that ships Steam hardware products to European users, was hit by a cyberattack between July 29 and August 1. Valve learned on August 7 that some personal information about Steam customers was "likely compromised." The stolen information includes names, addresses, phone numbers, emails and order details, according to Valve. CEVA does not have access to customers' payment info, passwords, Steam Guard codes or other sensitive information.

Valve warned affected customers to expect fake messages — email, SMS or phone — that mention their hardware order and appear to come from Steam, Valve or a delivery company. These messages might reference addresses or order details to convince recipients to pay a small customs or redelivery fee, or sign in somewhere to verify an order. Valve said it is pressing CEVA for the full scope of what was taken and how, and is in the process of notifying data protection authorities in the affected countries.

The Verge reported that the breach at CEVA occurred weeks after Valve began taking reservations for its new Steam Machine and Steam Controller. Valve added that CEVA stores delivery-related information for up to 90 days after orders, and that customers should treat any unsolicited messages about their orders as fake.